CVE-2020-29583

CRITICALCVSS 9.8/10Actively ExploitedEPSS 90.05%

Last modified

CVE-2020-29583 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. CISA has confirmed active exploitation in the wild. EPSS estimates a 90.05% chance of exploitation in the next 30 days.

Description

Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
90.05%

99.8th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersions
ZyxelUsg20-Vpn Firmware4.60
ZyxelUsg20w-Vpn Firmware4.60
ZyxelUsg40 Firmware4.60
ZyxelUsg40w Firmware4.60
ZyxelUsg60 Firmware4.60
ZyxelUsg60w Firmware4.60
ZyxelUsg110 Firmware4.60
ZyxelUsg210 Firmware4.60
ZyxelUsg310 Firmware4.60
ZyxelUsg1100 Firmware4.60
ZyxelUsg1900 Firmware4.60
ZyxelUsg2200 Firmware4.60
ZyxelZywall110 Firmware4.60
ZyxelZywall310 Firmware4.60
ZyxelZywall1100 Firmware4.60
ZyxelAtp100 Firmware4.60
ZyxelAtp100w Firmware4.60
ZyxelAtp200 Firmware4.60
ZyxelAtp500 Firmware4.60
ZyxelAtp700 Firmware4.60
ZyxelAtp800 Firmware4.60
ZyxelVpn50 Firmware4.60
ZyxelVpn100 Firmware4.60
ZyxelVpn300 Firmware4.60
ZyxelVpn1000 Firmware4.60
ZyxelUsg Flex 100 Firmware4.60
ZyxelUsg Flex 100w Firmware4.60
ZyxelUsg Flex 200 Firmware4.60
ZyxelUsg Flex 500 Firmware4.60
ZyxelUsg Flex 700 Firmware4.60

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2020-29583?
Firmware version 4.60 of Zyxel USG devices contains an undocumented account (zyfwp) with an unchangeable password. The password for this account can be found in cleartext in the firmware. This account can be used by someone to login to the ssh server or web interface with admin privileges.
How severe is CVE-2020-29583?
CVE-2020-29583 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 90.05% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2020-29583?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-29583?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST